2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34887 | MEDIUM | 4.9 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administr... |
| CVE-2024-34883 | MEDIUM | 4.9 | 0.4% | Nov 4, 2024 | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators... |
| CVE-2024-34882 | MEDIUM | 4.9 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato... |
| CVE-2024-51685 | MEDIUM | 4.8 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gan... |
| CVE-2024-51683 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Custom pos... |
| CVE-2024-51682 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Build... |
| CVE-2024-51681 | MEDIUM | 5.4 | 0.3% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP ... |
| CVE-2024-51680 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Cres... |
| CVE-2024-51678 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rat... |
| CVE-2024-51677 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Bas... |
| CVE-2024-51665 | MEDIUM | 4.3 | 0.5% | Nov 4, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor ... |
| CVE-2024-51408 | MEDIUM | 6.5 | 0.5% | Nov 4, 2024 | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to ... |
| CVE-2024-9147 | MEDIUM | 6.1 | 0.2% | Nov 4, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik... |
| CVE-2024-51560 | MEDIUM | 4.3 | 0.3% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint.... |
| CVE-2024-51559 | MEDIUM | 6.5 | 0.3% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticate... |
| CVE-2024-51557 | MEDIUM | 6.5 | 0.4% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authentica... |
| CVE-2024-51556 | MEDIUM | 6.5 | 0.2% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response.... |
| CVE-2024-10523 | MEDIUM | 4.6 | 0.1% | Nov 4, 2024 | This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device f... |
| CVE-2024-38405 | MEDIUM | 6.5 | 0.2% | Nov 4, 2024 | Transient DOS while processing the CU information from RNR IE. |
| CVE-2024-38403 | MEDIUM | 6.5 | 0.2% | Nov 4, 2024 | Transient DOS while parsing BTM ML IE when per STA profile is not included. |
| CVE-2024-33068 | MEDIUM | 6.5 | 0.2% | Nov 4, 2024 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
| CVE-2024-33032 | MEDIUM | 6.7 | 0.1% | Nov 4, 2024 | Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. |
| CVE-2024-33031 | MEDIUM | 6.7 | 0.1% | Nov 4, 2024 | Memory corruption while processing the update SIM PB records request. |
| CVE-2024-33030 | MEDIUM | 6.7 | 0.1% | Nov 4, 2024 | Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size. |
| CVE-2024-33029 | MEDIUM | 6.7 | 0.1% | Nov 4, 2024 | Memory corruption while handling the PDR in driver for getting the remote heap maps. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now